BlogSecurity
October 6, 2023

How Heyhack integrates automated pen testing with Vanta

Written by
Vanta
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Heyhack co-founders Sebastian Brandes and Anders Skovsgaard spotted a gap in the delivery of penetration testing. Most companies hire consultants to do their “pen test,” checking for security vulnerabilities at a single point in time. Hackers don’t take breaks, meaning breaches can occur at any point. Enter Hayhack, which runs automated penetration testing daily.  

“We launched last January [2022] with the goal of helping customers gain a complete overview of their entire application portfolio so they can remediate security issues quickly,” says Sebastian. “You set it up once and it will continually scan customers’ applications for vulnerabilities so they can be remediated before they are exploited.”

Building a growth strategy for companies of all sizes

Heyhack faced the dual challenges of establishing a steady income stream from smaller businesses while simultaneously demonstrating their value to entice larger enterprises to buy their product.

The co-founders saw a market for penetration testing services dominated by consultants. When a company requires a pen test for its SOC 2 or other certification, they traditionally use an auditor or other outside expert. These consultants cost additional time and money. 

The larger enterprises Heyhack was pursuing already have a complex security ecosystem, making it challenging to get an audience to explain how Heyhack can be a complementary tool in their toolkit. Their sales cycle also is much longer than a start-up business, a key point Sebastian and Anders needed to factor into their growth plan.

Partnering with a leader embedded in their target market

“We are a customer of Vanta. We love what they’ve built and the fact that they bundle together everything you need into one service and that all the support comes in one package with a clear and fixed price. I’ve been recommending them to friends of mine who’ve started companies as well,” says Sebastian. 

“Pretty soon it became obvious to us that many of the companies interested in Vanta and its automated security and compliance platform will also need a pen test. It became clear that we should just go ahead and build an integration, which we can also use ourselves.”

Heyhack became a Vanta Technology Partner and worked directly with Vanta and its Connectors API to build an integration. The Vanta team enhanced the API to be able to receive the type of data Heyhack needed to transmit for vulnerability and compliance tracking. “It was a super experience, a 10 out of 10,” says Sebastian. “Other partners are more set in stone. Vanta has been so flexible and forthcoming.”

The integration enables Heyhack to continually run pen tests for shared customers. The high-level results are collected in Vanta’s platform while code snippets and other details are shared directly with a customers’ development team to demonstrate any vulnerabilities or concerns.

Opening doors to new business every day

To get a SOC 2, companies must collect evidence and proof points to support their security claims. 

“With this integration, this is one less thing that companies need to do manually,” says Sebastian. “We’re definitely making our customers’ lives easier and at a much more reasonable price.” Within two weeks of launch, a handful of their shared customers had already signed up to take advantage of the integration.

The company offers a free trial, but Vanta customers who request an introduction from the Vanta Partners page skip that step and immediately book a meeting to talk about buying. Heyhack has also been able to schedule meetings with larger enterprises that are starting to see the value of the product. Heyhack’s automated pen testing allows customers to test for the types of things they don’t have the human resources to dedicate to.

 “There's been a commercial upside to building this integration that’s been super positive for us,” says Sebastian, “but ultimately we've also been able to provide a better service for our common customers. Vanta has set out to make it easy to automate as much as possible around compliance and for partners to integrate quickly and easily as well. Through this integration, we’ve been able to help customers easily identify vulnerabilities in their software.”

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.